Home / Privacy Policy

Legal

Privacy Policy

How CyberSecOps collects, uses and protects personal information through this website and in the course of delivering engineering services.

Template content. Review and adapt with qualified legal counsel before publication. Every bracketed value must be replaced.

Effective date: [EFFECTIVE DATE]

Last updated: [LAST UPDATED DATE]

01Who we are

This policy is issued by [LEGAL ENTITY NAME] (“CyberSecOps”, “we”, “us”), registered at [REGISTERED ADDRESS]. It applies to cybersecops.dev and to personal information we handle when providing services to our clients.

For privacy questions, contact [PRIVACY CONTACT EMAIL]. Where required by law, our data protection representative is [DATA PROTECTION OFFICER OR REPRESENTATIVE].

02Information we collect

We collect the information you give us directly and a limited amount of technical information generated when you use this site.

  • Contact and enquiry details you submit: name, work email address, organization, region and the content of your message
  • Correspondence, including email and meeting records relating to an enquiry or engagement
  • Technical data such as IP address, browser type, device type, referring page and pages viewed
  • Client environment information processed under a services agreement, on the instructions of that client

We do not ask for special-category personal data through this website, and we ask that you do not include it in enquiry messages.

03How we use information

We use personal information to respond to enquiries, to scope, deliver and support engineering services, to manage our contractual and business relationships, to secure and improve this website, and to meet our legal and regulatory obligations.

We do not sell personal information, and we do not use enquiry details for unrelated marketing without a separate, clearly given consent.

04Legal bases

Where [APPLICABLE DATA PROTECTION LAW] requires a legal basis, we rely on: performance of a contract or steps taken at your request before entering one; our legitimate interests in operating and securing our business, balanced against your rights; compliance with a legal obligation; and consent, where consent is the appropriate basis. Consent may be withdrawn at any time.

05Service providers and disclosure

We share personal information with vetted providers who support our operations — for example hosting, communications, and business administration — under contracts that restrict their use of it to our instructions.

We may also disclose information where required by law, to establish or defend legal claims, or in connection with a corporate transaction, subject to appropriate safeguards. A current list of categories of processors is available on request from [PRIVACY CONTACT EMAIL].

06International transfers

Where personal information is transferred outside [PRIMARY JURISDICTION], we put in place a recognized transfer mechanism such as standard contractual clauses, together with technical measures appropriate to the sensitivity of the data.

07Retention

We keep enquiry correspondence for [ENQUIRY RETENTION PERIOD] unless it becomes part of a client relationship, in which case records are retained for the duration of the engagement plus [CLIENT RETENTION PERIOD] to meet contractual, tax and legal requirements. Client environment data is retained and deleted according to the terms of the applicable services agreement.

08How we protect information

We maintain technical and organizational measures appropriate to the risk, covering access management, encryption in transit and at rest, secrets management, endpoint protection, logging and monitoring, and a documented incident response process.

[CONFIRM THIS LIST MATCHES THE CONTROLS YOU ACTUALLY OPERATE BEFORE PUBLICATION — a privacy policy is an enforceable representation, not a statement of intent.]

No system is perfectly secure. If a breach affects your personal information and the law requires notification, we will notify you and the relevant supervisory authority within the required timeframe.

09Your rights

Subject to the law that applies to you, you may request access to your personal information, correction of inaccurate data, deletion, restriction of or objection to processing, and portability. Where we act as a processor for a client, we will refer your request to that client and support their response.

To exercise a right, contact [PRIVACY CONTACT EMAIL]. We will verify your identity before acting, and respond within the period required by [APPLICABLE DATA PROTECTION LAW]. You may also complain to your supervisory authority, [SUPERVISORY AUTHORITY].

10Cookies and analytics

This site uses strictly necessary cookies to function, and [ANALYTICS PROVIDER, OR “no analytics cookies”] to understand aggregate usage. Non-essential cookies are set only after you consent.

To change or withdraw a cookie choice, or to ask what is set on your device, contact [PRIVACY CONTACT EMAIL]. [IF YOU DEPLOY A CONSENT BANNER, REPLACE THIS SENTENCE WITH A LINK TO ITS PREFERENCES CONTROL.]

11Children

This website and our services are directed at organizations and are not intended for children. We do not knowingly collect personal information from anyone under the age of [MINIMUM AGE].

12Changes to this policy

We update this policy when our practices or legal obligations change. Material changes will be highlighted on this page, and the effective date above will be revised.

13Contact us

Questions about this policy, or about how we handle personal information, can be sent to [PRIVACY CONTACT EMAIL] or by post to [REGISTERED ADDRESS]. Suspected security vulnerabilities should instead be reported to security@cybersecops.dev.